linux-kernel.vger.kernel.org archive mirror
 help / color / mirror / Atom feed
* crypto_memneq not backported to 3.10
@ 2017-04-09 12:59 Jason A. Donenfeld
  2017-04-09 13:25 ` Willy Tarreau
  0 siblings, 1 reply; 4+ messages in thread
From: Jason A. Donenfeld @ 2017-04-09 12:59 UTC (permalink / raw)
  To: Willy Tarreau, stable; +Cc: LKML, Linux Crypto Mailing List

Hey Willy,

Linux 3.10 is inexplicably missing crypto_memneq, making all crypto
mac comparisons use non constant-time comparisons. Bad news bears.

3.12 got these backported with
d68e944a8fcb2c6212b38064771c9f5af7b0b92c,
afe5a791d374e50a06ada7f4eda4e921e1b77996, and possibly others. I'd
suggest following suit, since many people are relying on this kernel
to do safe crypto.

Thanks,
Jason

^ permalink raw reply	[flat|nested] 4+ messages in thread

end of thread, other threads:[~2017-05-01 14:48 UTC | newest]

Thread overview: 4+ messages (download: mbox.gz / follow: Atom feed)
-- links below jump to the message on this page --
2017-04-09 12:59 crypto_memneq not backported to 3.10 Jason A. Donenfeld
2017-04-09 13:25 ` Willy Tarreau
2017-05-01 14:30   ` Jason A. Donenfeld
2017-05-01 14:48     ` Willy Tarreau

This is a public inbox, see mirroring instructions
for how to clone and mirror all data and code used for this inbox;
as well as URLs for NNTP newsgroup(s).